PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-63947 Linux CVE debrief

A vulnerability was found in the Linux kernel's Bluetooth HIDP implementation. The hidp_input_report() function does not properly verify the length of the input report, leading to an out-of-bounds read when a paired device sends a truncated packet. This can result in phantom key presses or spurious mouse movement. The issue is resolved by replacing open-coded length tracking and pointer arithmetic with skb_pull_data() calls, which return NULL if the requested bytes are not present. Linux kernel developers, Linux distribution maintainers, and users of Linux-based systems with Bluetooth HIDP devices should review and apply the kernel patch.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-19
Original CVE updated
2026-07-19
Advisory published
2026-07-19
Advisory updated
2026-07-19

Who should care

Linux kernel developers, Linux distribution maintainers, and users of Linux-based systems with Bluetooth HIDP devices should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing and applying the kernel patch, verifying Linux kernel and distribution versions for updates, and monitoring Bluetooth HIDP device usage and system logs for suspicious activity.

Technical summary

The Linux kernel's Bluetooth HIDP implementation is vulnerable to an out-of-bounds read due to a missing length check in the hidp_input_report() function. This can be exploited by a paired device sending a truncated packet, potentially leading to phantom key presses or spurious mouse movement. The issue is resolved by replacing open-coded length tracking and pointer arithmetic with skb_pull_data() calls, which return NULL if the requested bytes are not present.

Defensive priority

Medium

Recommended defensive actions

  • Review and apply the kernel patch
  • Verify Linux kernel and distribution versions for updates
  • Monitor Bluetooth HIDP device usage and system logs for suspicious activity
  • Consider implementing additional logging and monitoring for kernel events
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-07-19T16:17:13.337Z and has not been modified since then. The NVD entry is currently Received. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the official CVE record and vendor guidance.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-19T16:17:13.337Z and has not been modified since then.